Legal information

Responsible disclosure

If you find a flaw on our sites, we would rather hear it from you than from an attacker. This page sets out how to report it and what we commit to in return.

/01

Scope

This policy covers the assets we operate ourselves.

  • groupitcs.ca and its subdomains;
  • virementfrauduleux.com;
  • the server function that receives the site forms.
/02

What this policy does not cover

Our clients systems fall outside this policy, even where we work on them under an engagement. Testing those systems requires written authorization from their owner.

/03

How to report a flaw

Write to [email protected] with the asset concerned, a description of the flaw, the steps to reproduce it, the impact you estimate and, where possible, a capture or a trace. French and English are both fine.

If you would rather use an encrypted channel, ask for one in a first message without technical detail and we will open it.

/04

Our commitments

We pay no bounty, but we do answer and we do fix.

  • acknowledgement of receipt within 3 business days;
  • first assessment and an answer on admissibility within 10 business days;
  • notice once the fix has been deployed;
  • credit under your name in our acknowledgements if you wish;
  • no lawsuit and no complaint from us against a researcher who follows the rules below.
/05

Rules to follow

These rules define the frame within which our commitment not to pursue you holds.

  • keep to the minimum proof of concept, going no further than what demonstrates the flaw;
  • do not access, alter, extract or retain information belonging to a third party, and stop the test as soon as such data appears;
  • no denial of service, no load testing, no bulk submissions through the forms;
  • no social engineering or phishing aimed at our employees, our providers or our offices;
  • do not disclose the flaw publicly before it is fixed or before a 90 day period agreed together has elapsed.
/06

Reports we do not act on

The following are closed without action, for lack of a workable demonstration.

  • raw scanner output, with no demonstrated impact;
  • a missing security header or DNS record, with no associated exploitation;
  • theoretical weaknesses in a cipher suite still broadly accepted;
  • scenarios requiring physical access to the victim device or an unsupported browser;
  • reports concerning a third-party service, which should go to its vendor directly.
/07

security.txt file

A file compliant with RFC 9116 carries these details at the root of our domains, for the tools that look for it automatically.

Last revised: August 18, 2026